Info: Bounced: DCID 8413617 MID 19338947 From: <MariaDubois@example.com> To: <abcdef@buttercupgames.com> RID 0 - 5.4.7 - Delivery expired (message too old) ('000', ['timeout'])
O/p:
from_mail_id = MariaDubois@example.com
to_mail_id = abcdef@buttercupgames.com
Please help me with the Solution ,Thanks
Thank you Sir ,But need the Solution using only Regex .
Please help, Thanks in advance
Hi
if you want to pick those values from events then you need a rex and if you want to select events which contains that kind of parts, but don't want to select those to the new fields then you should use regex.
r. Ismo
Hi
You could try this (I suppose that you have above data already in splunk _raw field).
... <your search> ..
| rex "From: <(?<from_mail_id>[^>]+)> To: <(?<to_mail_id>[^>]+)>"
r. Ismo
Hi @isoutamo sir
How to extract this event into four different counts using rex
1234-5678-9101-1213
example : Count1-1234 count2-5678 and so on.....
please help me with solution, thanks in advance
You could use e.g this
...
| rex "(?<count-1>\d+)-(?<count-2>\d+)-(?<count-3>\d+)-(?<count-4>\d+)"
You can learn to use rex with regex101.com https://regex101.com/r/ZPQDgg/1